Executive brief
FluidSynth is a software synthesizer used to generate audio from MIDI commands and SoundFont files. A flaw in the pitch_bend_range command handler fails to validate the channel number before writing to memory, allowing an attacker to trigger a heap buffer overflow. This can cause the synthesizer to crash or potentially execute arbitrary code when the TCP server is enabled or when processing untrusted commands through the shell.
Technical details
The pitch_bend_range command handler accepts a channel argument that is not bounds-checked before being used as an array index to write to the synth's channel array, resulting in an out-of-bounds heap write. The vulnerability is reachable remotely when the TCP server is enabled via new_fluid_server() or the -s flag, and locally through malicious input to the shell interface. A bounds check added in version 2.5.6 mitigates the issue.
Affected products
- FluidSynth FluidSynth 1.1.2 to 2.5.5
Timeline
- 2026-09-18: disclosed
- 2026: patched: Fixed in version 2.5.6